SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status no, high risk).

Detector
sanctions_or_pep
Severity
high
Program
Meridian Remit (simulated)
Subject
entity enti_sim_meri_5if3mzfr9pn
Transfer
acht_sim_meri_ah47837rc0h · $354.20 · ach outgoing
Skoor at alert
20 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An alert fired on 2026-09-17 for entity enti_sim_meri_5if3mzfr9pn under the sanctions_or_pep detector after a settled ACH debit of $354.20 on 2026-09-06 from that entity, part of the Meridian Remit program (declared monthly volume $1,200,000.00, rails ach/wire/swift, countries US/MX/PH). What the evidence shows. The transfer-level skoor is 20, band clear, with hard_signal false. The only contributing signal is entity.high_risk (+20). The entity record shows verification status VERIFIED, pep=no, review reasons none, last screened 2026-08-27 (not stale), and country US. The transfer itself is SETTLED with no return code, indicating no rejection or reversal. There are no prior dispositions on this alert. Program-level KRIs show several breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate, sanctioned_country_transfers=1), but none of these are tied in the evidence to this specific entity or transfer. What was checked. Reviewed the alert's skoor, band, and hard_signal fields; the entity's screening, verification, and PEP status; the transfer's status and return code; and the program's KRI panel for any linkage to this subject. No stale screening, no PEP flag, no denial or return on the transfer, and no prior alert history were found. What is recommended. Close this alert. The screening result is clear-band with no hard signal, the entity is verified and not PEP, screening is current, and the associated transfer settled without incident. The program-level KRI breaches (e.g., sanctioned_country_transfers, reserve_coverage_ratio) are noted for program-level monitoring but do not, on this evidence, tie to this specific entity or transfer, so they do not change the disposition of this alert. A person should still review program KRI breaches separately if not already tracked elsewhere.
Recommendation
close
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer skoor is 20, band clear, hard_signal false — the only signal present is entity.high_risk, already accounted for in the low score.
  • Entity is VERIFIED, pep=no, review reasons none, and screening is current (2026-08-27), showing no stale or unresolved screening issue.
  • The associated transfer is SETTLED with return code none, showing no rejection, reversal, or unauthorized-return event tied to this specific activity.
  • No prior dispositions exist on this subject, so there is no pattern of repeat alerts to escalate.
  • Program-level KRI breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate, sanctioned_country_transfers) are present but not evidenced as connected to this entity or transfer, so they are noted as context rather than grounds for escalation on this alert.
  • The transfer has already settled, so a hold or release recommendation does not apply.

Evidence

{
  "n": 902,
  "band": "clear",
  "skoor": 20,
  "signals": [
    {
      "code": "entity.high_risk",
      "detail": "entity marked high risk by screening",
      "weight": 20
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.high_risk+20entity marked high risk by screening

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.